← All articles
Collections

RBI-compliant AI collections in India: turning conduct rules into controls

India's recovery-conduct norms are written around behaviour, not the caller. That is why an AI voice agent, acting through logged tools, can enforce them more reliably than a human floor.

The short answer

You make AI voice collections RBI-compliant by building the Fair Practices Code conduct rules into the agent, logging every call for full audit, and meeting DPDP consent and purpose-limitation duties.

What conduct do India's collections rules actually expect?

Debt recovery in India runs on a simple principle. You can pursue what is owed, but never the borrower's dignity. The RBI's Fair Practices Code and its expectations for recovery agents set the tone, and a customer in default is still a customer the rules protect.

Strip away the legal language and a compliant collections call looks like this:

  • No harassment or intimidation: no threats, no abusive language, and no pressure routed through the borrower's family or neighbours.
  • Calls only within permitted hours, not late at night or early in the morning.
  • The agent identifies themselves, the institution they represent, and why they are calling.
  • A respectful tone throughout, even when the borrower is difficult.
  • A clear route to raise a grievance, and a record that the borrower was told about it.

None of this is exotic. Any bank or NBFC running a recovery function knows these rules, and the regulated lender stays accountable for how recovery is conducted on its behalf, whoever or whatever places the call. The rules were never the hard part. Enforcing them on every collections call, across a floor of agents, at the tired end of a long shift, is where the exposure has always sat.

The Conduct Principles
No harassment
No threats, no pressure through others
Permitted hours
No late-night or early-morning calls
Clear identification
Agent, institution, and purpose
Grievance route
Told, and recorded that they were
India's recovery rules are written around behaviour, not the caller.

Where does the DPDP Act 2023 fit in?

Conduct is one half of the picture. Data is the other. The Digital Personal Data Protection Act 2023 governs how you handle the borrower's personal data, and collections touches plenty of it: phone numbers, outstanding amounts, employment details, sometimes hardship context shared in confidence.

These duties also sit at principle level. You need a lawful basis to process the data, usually consent or a purpose tied to the loan. You use it only for the purpose you collected it for, protect it with reasonable security, and keep records that show you did. For a voice programme, that means being deliberate about how the voicebot stores and handles that data.

Two things are worth holding onto for a collections programme: the borrower's consent and its scope, and a trail proving the data served recovery and nothing else. A voice agent that logs every input and every action makes that trail easier to produce, not harder.

Is an AI voice agent a new compliance risk, or a control?

Most risk teams meet AI voice collections as a worry first. A machine calling borrowers sounds like a headline waiting to happen, and that instinct deserves a proper hearing rather than a brush-off.

So look at where the risk actually lives on a human floor. An agent can lose their temper, dial outside permitted hours because the dialler pushed a number, skip the identification script under pressure, or promise something they should not. And you find out only if that particular call lands in the small share that QA happens to review.

Compliance on a human floor is mostly a hope backed by a sample. On an AI floor it is a control backed by a log.

An AI agent acts through tools, and every tool call is logged. Configure the calling hours and it simply cannot dial outside them. The identification line lives inside the flow, so it runs every time rather than depending on a memory that fatigue wears down. By call 300 the agent is as measured as it was at call one. None of this makes the machine cleverer than a good human agent. It makes the boundaries structural instead of a matter of discipline, which is what a risk reader is really being asked to trust.

Hope Versus A Log

Human floor

  • Hours rely on discipline; slips happen
  • ID script only if remembered
  • Tone varies with mood and fatigue
  • QA reviews a small sample

AI voice agent

  • Cannot dial outside set hours
  • ID line built into the flow
  • Consistent, even at call 300
  • 100% captured and scored
On a human floor compliance is a hope; on an AI floor it is a control.

How does AI turn compliance from a hope into a control?

The difference that matters most to a risk reader is coverage. A human floor is audited by sampling: you listen to a slice of calls, score them, and infer the rest. An AI floor can be audited in full. Every interaction is captured, transcribed, and scored against your conduct rules automatically, around the clock, and we run this at 100% audit coverage across the interactions we handle, so the record is the whole population of calls and not a hopeful cut of it.

That changes what an audit even is. Instead of asking whether a breach happened somewhere in the calls nobody heard, you search every call for the pattern and know. A regulator's question stops being an argument and becomes a query.

None of this is automatic. An AI agent is only as compliant as the guardrails around it. Before you sign off a live deployment, a risk or legal team should hold out for a short, specific list:

  • Guardrails: configurable calling hours, a locked identification and disclosure script, and hard limits on what the agent may say or promise.
  • Audit: a complete, timestamped log of every call, transcribed and scored against your conduct rules, retained for the period your policy demands. Ask to run a live query against it yourself, not just read a sample report.
  • Consent and purpose: proof of the borrower's consent, its scope on record, and controls that stop the data being used for anything beyond recovery.
  • Data residency and sub-processors: a full map of where the data is stored and processed, and which third-party speech services touch it along the way, all behind a recognised security standard. We hold ISO 27001 certification for our information security management.
  • Escalation: a clean handover to a human the moment a call turns to a dispute, hardship, or a grievance. The agent runs the routine, compliant conversation; a borrower in real difficulty is a person's job, not the model's.

Get those five in writing and the compliance question moves from trust to evidence. That is the entire point of running it this way.

NOTE

This article describes India's recovery-conduct expectations and the DPDP Act 2023 at the level of established principles. It is not legal advice. Rules change, and your exact obligations depend on your institution, your regulator, and your data-protection posture. Confirm the current requirements with your own compliance and legal teams before you act.

Require Before Go-Live
GuardrailsConfigured hours, locked script, hard limitsFull auditEvery call transcribed, scored, retainedConsent & purposeScope recorded, use limited to recoveryData residency & securityKnown storage behind ISO 27001EscalationClean human handover for disputes
An AI agent is only as compliant as the guardrails around it.

Manual floor vs AI voice agent: compliance controls

Human collections floorAI voice agent

Frequently asked questions

Does the RBI allow AI voice bots to make collections calls?

India's recovery-conduct rules are written around behaviour, not the caller's identity. They require no harassment, permitted calling hours, clear identification, respectful conduct, and grievance access. An AI voice agent can meet each of these if it is configured to, and if it identifies itself as an automated assistant. The obligation is to conduct the call properly, whoever or whatever places it.

How does an AI agent stay within permitted calling hours?

Calling hours are set as a hard rule in the agent's configuration, not left to a person watching the clock. The agent cannot place a call outside the window you define, and every attempt is logged. On a human floor the same rule leans on dialler settings and individual discipline, which is where slips tend to creep in.

What does the DPDP Act 2023 require for collections data?

At principle level, you need a lawful basis to process the borrower's personal data, usually consent or a purpose tied to the loan. You use it only for that purpose, protect it with reasonable security, and keep records showing you did. A logged AI agent makes the record-keeping and purpose-limitation trail easier to produce than a human floor does.

Can an AI collections agent handle disputes and grievances?

It should not try to. A well-designed agent recognises disputes, hardship, and grievances, then hands the call to a human with full context. The rule of thumb is simple: the agent runs the routine, compliant conversation and escalates anything that needs judgement or a human ear. The handover itself is logged, so you can prove the borrower was routed correctly.

How is a fully auditable AI floor different from human QA?

Human QA samples. It listens to a slice of calls, scores them, and infers the rest, so a breach can sit undetected in the calls nobody heard. An AI floor captures, transcribes, and scores every interaction automatically. We run this at 100% audit coverage. An audit stops being an argument about the unheard calls and becomes a search across all of them.

O
Oriserve
AI for BFSI · Oriserve

Oriserve builds the outcome-execution platform for contact-centre processes — AI agents that run collections, renewals, retention and support calls, with a person on the exceptions.

ShareinX

Hear an AI agent handle a real call — in 30 seconds.

Get a call →or book a full demo